Support Center

NeXpose FAQ - Evaluation & Pre-Deployment Answers

Is it possible to evaluate NeXpose?

Yes, we offer free 20 day evaluations of NeXpose. To get your evaluation copy, go to the Rapid7 Web site and fill out a download request form.You will then receive an email from the “Download Request Manager” containing a link to download NeXpose. Click on the link and NeXpose will download to your computer.

Back

How do I get an evaluation license for NeXpose extended?

Contact your Rapid7 Presales representative to extend your evaluation license.

Back

How do I contact Rapid7 Technical Support?

Rapid7 Technical Support may be contacted by phone or email:

Back

What are the minimum system requirements for installation?

  • Dedicated server with no IPS/IDS/Virus Scanning
  • 1.5 GHz processor and later
  • 2 GB RAM for 32-bit installs; 8 GB RAM for 64-bit installs
  • 80 GB + available disk space (10 GB minimum)
  • 100Base-TX Network Interface Card

Back

What operating systems does NeXpose run on?

NeXpose can run on many operating systems, including the following officially-supported platforms.

  • MS Windows Server 2003 SP2 / Server 2003 R2
  • Red Hat Enterprise Linux 5
  • Ubuntu 8.04 LTS
  • SuSE Linux Enterprise Server 10

NeXpose may run on other Linux distributions but it is only officially supported and validated on the Operating Systems listed above.

 

Back

Does NeXpose run on VMware?

NeXpose will run, and is supported, when installed on a properly configured VMware environment. Rapid7 does not support the installation or configuration of the VMware environment. This is due to the complicated setup process of VMware itself and actually establishing a optimum operating conditions. In VMware, we have seen the first run of NeXpose (which includes downloading updates and compiling databases) take up to an hour depending on how VMware is set up. If you are not experienced with VMware, we highly recommend installing on Windows 2000, Windows 2003, or Linux.

Back

I want to evaluate or have already purchased NeXpose. How do I request a copy of the software?

To request a copy of the NeXpose software, go to the Rapid7 Web site and fill out a download request form. You will then receive an email from the “Download Request Manager” containing a link to download NeXpose. Click on the link and NeXpose will download to your computer.

Back

When I click on my download link I receive the error: Invalid Download Request?

This generally means the one time use link has already been used to attempt a download. If the download is interrupted, the link will become invalid and a new Download Request will be required. If you have received this error with multiple/unique download links please contact Rapid7 Technical Support for further assistance.

Back

How do I install on Windows?

Once the NeXpose download has completed, start the installer and then start the product (it will take a few minutes for the vulnerability definitions to compile). When the installation is complete, a message will appear 'Ready to browse to https:...' Open IE or Firefox and connect to the NeXpose browser-based interface.

Back

How long does a scan take?

  • Ping Sweep of 10 million IPs 5-10 hours: - This time depends on the physical distance and latency of the line between NeXpose and the target system. The assumption is approx. 150ms per IP.
  • Port Scan of 3000 devices (default ports/SYN scan) 16-18 hours - This is relatively easy to predict since open ports do not affect the speed of a SYN scan. A full connect scan will be slower based on the number of open ports. Also varies based upon the distance between the devices and the latency on the line. The assumption is approx. 45 seconds per device.
  • Vulnerability Scan of 1500 devices 15-20 hours - This widely varies based on the number of ports open per device. The more ports open on a machine the longer it will take to conduct the vulnerability scan. The assumption is approx. 2 minutes per device.

Back

How does NeXpose ensure efficient bandwidth utilization?

NeXpose uses customizable scan templates and the user can specify the packet send delay, timeouts, maximum number of scan threads, and concurrent port scans. Furthermore, NeXpose will only run the vulnerability checks appropriate to the type of machine scanned (for example, no test specific to Linux operating systems will be run against a Windows machine.)

Back

 Rapid7’s support during our product trial was excellent, and since our purchase it has consistently been great. If we need help or have a question, we always get a live person."

Joe Ferris
Network Security Engineer
IT Security Team, Florida State University